fix(forgejo-runner): cicd ns PSS privileged (dind needs it) + mount homelab-ca as ConfigMap not Secret — runner RS created 0 pods under baseline PSS, then FailedMount because homelab-ca is a ConfigMap trust bundle, not a Secret
This commit is contained in:
@@ -3,8 +3,10 @@ kind: Namespace
|
||||
metadata:
|
||||
name: cicd
|
||||
labels:
|
||||
# Baseline allows most workloads while blocking clearly dangerous configurations
|
||||
# Redis needs some relaxed settings but doesn't need full privileged access
|
||||
pod-security.kubernetes.io/enforce: baseline
|
||||
pod-security.kubernetes.io/audit: baseline
|
||||
pod-security.kubernetes.io/warn: baseline
|
||||
# privileged: the forgejo-runner's dind (docker-in-docker) sidecar requires
|
||||
# securityContext.privileged=true, which baseline/restricted PSS reject
|
||||
# (the ReplicaSet silently creates 0 pods). gitea, redis and CNPG here are
|
||||
# already privileged-tolerant.
|
||||
pod-security.kubernetes.io/enforce: privileged
|
||||
pod-security.kubernetes.io/audit: privileged
|
||||
pod-security.kubernetes.io/warn: privileged
|
||||
|
||||
@@ -104,5 +104,7 @@ spec:
|
||||
- name: docker-certs
|
||||
emptyDir: {} # DinD regenerates mTLS certs on each start
|
||||
- name: homelab-ca
|
||||
secret:
|
||||
secretName: homelab-ca
|
||||
# homelab-ca is a ConfigMap (public CA trust bundle), not a Secret.
|
||||
# The volumeMounts use subPath: ca.crt to project the single cert file.
|
||||
configMap:
|
||||
name: homelab-ca
|
||||
|
||||
Reference in New Issue
Block a user